mirror of
https://github.com/suitenumerique/docs.git
synced 2026-09-03 07:08:47 +02:00
Add POST /collaboration/reset-connections/v1/{org}/{docid} (optional
X-User-Id header) to yhub-server. It distributes yhub recheckAuth: every
server re-runs the access check per matching connection and closes only
those whose access actually changed (close code 4401), so unaffected
clients see no reconnect churn. The endpoint authenticates with the
RS256 admin JWT issued by JWTService, verified against the backend JWKS
(new jose dependency); the admin token acts as the "system" user and is
the only principal granted the reset-connections access purpose. The
backend does not trigger it on permission changes yet - that wiring
comes separately, now that CollaborationService is gone.
yhub is upgraded to 0.4.0 and serves every route under the
/collaboration/ prefix (server.apiPrefix): the websocket moves to
/collaboration/ws/v1/docs, and the built-in document apis are meant to
be publicly exposed alongside it, with reset-connections as the one
backend-internal exception.
Also harden websocket auth: fail closed when the backend errors (only a
genuine 401/403 falls back to the anonymous identity, so a signed-in
editor can never hide from a targeted recheck under an anon userid) and
tolerate small clock skew when verifying the cached admin token.
Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
103 lines
3.6 KiB
Plaintext
103 lines
3.6 KiB
Plaintext
# Django
|
|
DJANGO_ALLOWED_HOSTS=*
|
|
DJANGO_SECRET_KEY=ThisIsAnExampleKeyForDevPurposeOnly
|
|
DJANGO_SETTINGS_MODULE=impress.settings
|
|
DJANGO_SUPERUSER_PASSWORD=admin
|
|
|
|
# Logging
|
|
# Set to DEBUG level for dev only
|
|
LOGGING_LEVEL_HANDLERS_CONSOLE=INFO
|
|
LOGGING_LEVEL_LOGGERS_ROOT=INFO
|
|
LOGGING_LEVEL_LOGGERS_APP=INFO
|
|
|
|
# Python
|
|
PYTHONPATH=/app
|
|
|
|
# impress settings
|
|
|
|
# Mail
|
|
DJANGO_EMAIL_BRAND_NAME="La Suite Numérique"
|
|
DJANGO_EMAIL_HOST="mailcatcher"
|
|
DJANGO_EMAIL_LOGO_IMG="http://localhost:3000/assets/logo-suite-numerique.png"
|
|
DJANGO_EMAIL_PORT=1025
|
|
DJANGO_EMAIL_URL_APP="http://localhost:3000"
|
|
|
|
# JWT
|
|
# The key itself is generated locally by "make generate-secret-keys", it is
|
|
# never committed. A PEM does not fit in an env var, hence the _FILE variant.
|
|
JWT_PRIVATE_KEY_FILE=/data/jwt/private.pem
|
|
|
|
# Backend url
|
|
IMPRESS_BASE_URL="http://localhost:8072"
|
|
|
|
# Media
|
|
STORAGES_STATICFILES_BACKEND=django.contrib.staticfiles.storage.StaticFilesStorage
|
|
AWS_S3_ENDPOINT_URL=http://minio:9000
|
|
AWS_S3_ACCESS_KEY_ID=impress
|
|
AWS_S3_SECRET_ACCESS_KEY=password
|
|
MEDIA_BASE_URL=http://localhost:8083
|
|
|
|
# OIDC
|
|
OIDC_OP_JWKS_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/certs
|
|
OIDC_OP_AUTHORIZATION_ENDPOINT=http://localhost:8083/realms/impress/protocol/openid-connect/auth
|
|
OIDC_OP_TOKEN_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/token
|
|
OIDC_OP_USER_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/userinfo
|
|
OIDC_OP_INTROSPECTION_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/token/introspect
|
|
|
|
OIDC_RP_CLIENT_ID=impress
|
|
OIDC_RP_CLIENT_SECRET=ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_RP_SIGN_ALGO=RS256
|
|
OIDC_RP_SCOPES="openid email"
|
|
|
|
LOGIN_REDIRECT_URL=http://localhost:3000
|
|
LOGIN_REDIRECT_URL_FAILURE=http://localhost:3000
|
|
LOGOUT_REDIRECT_URL=http://localhost:3000
|
|
|
|
OIDC_REDIRECT_ALLOWED_HOSTS="localhost:8083,localhost:3000"
|
|
OIDC_AUTH_REQUEST_EXTRA_PARAMS={"acr_values": "eidas1"}
|
|
|
|
# Resource Server Backend
|
|
OIDC_OP_URL=http://localhost:8083/realms/docs
|
|
OIDC_OP_INTROSPECTION_ENDPOINT = http://nginx:8083/realms/docs/protocol/openid-connect/token/introspect
|
|
OIDC_RESOURCE_SERVER_ENABLED=False
|
|
OIDC_RS_CLIENT_ID=docs
|
|
OIDC_RS_CLIENT_SECRET=ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_RS_AUDIENCE_CLAIM="client_id" # The claim used to identify the audience
|
|
OIDC_RS_ALLOWED_AUDIENCES=""
|
|
|
|
# Store OIDC tokens in the session. Needed by search/ endpoint.
|
|
# OIDC_STORE_ACCESS_TOKEN=True
|
|
# OIDC_STORE_REFRESH_TOKEN=True # Store the encrypted refresh token in the session.
|
|
|
|
# Must be a valid Fernet key (32 url-safe base64-encoded bytes)
|
|
# To create one, use the bin/fernetkey command.
|
|
# OIDC_STORE_REFRESH_TOKEN_KEY="your-32-byte-encryption-key=="
|
|
|
|
# User reconciliation
|
|
USER_RECONCILIATION_FORM_URL=http://localhost:3000
|
|
|
|
# Collaboration
|
|
COLLABORATION_BACKEND_BASE_URL=http://app-dev:8000
|
|
COLLABORATION_SERVER_ORIGIN=http://localhost:3000
|
|
COLLABORATION_SERVER_SECRET=my-secret
|
|
COLLABORATION_WS_URL=ws://localhost:3002/collaboration/ws/v1/docs
|
|
COLLABORATION_WS_INACTIVITY_TIMEOUT=15 # Seconds
|
|
|
|
DJANGO_SERVER_TO_SERVER_API_TOKENS=server-api-token
|
|
Y_PROVIDER_API_BASE_URL=http://y-provider-development-converter:4444/api/
|
|
Y_PROVIDER_API_KEY=yprovider-api-key
|
|
|
|
DOCSPEC_API_URL=http://docspec:4000/conversion
|
|
|
|
# Theme customization
|
|
THEME_CUSTOMIZATION_CACHE_TIMEOUT=15
|
|
|
|
# Indexer (disabled by default)
|
|
# SEARCH_INDEXER_CLASS=core.services.search_indexers.FindDocumentIndexer
|
|
SEARCH_INDEXER_SECRET=find-api-key-for-docs-with-exactly-50-chars-length # Key generated by create_demo in Find app.
|
|
INDEXING_URL=http://find:8000/api/v1.0/documents/index/
|
|
SEARCH_URL=http://find:8000/api/v1.0/documents/search/
|
|
SEARCH_INDEXER_QUERY_LIMIT=50
|
|
|
|
CONVERSION_UPLOAD_ENABLED=true
|